Description
MySQL 5.0 before 5.0.66, 5.1 before 5.1.26, and 6.0 before 6.0.6 does not properly handle a b'' (b single-quote single-quote) token, aka an empty bit-string literal, which allows remote attackers to cause a denial of service (daemon crash) by using this token in a SQL statement.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2007-2114 Vulnerability (CVE-2007-2114)
WebLogic Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2022-22965)
WordPress Plugin Shoppable Images Multiple Vulnerabilities (1.2.3)
WordPress Plugin Media File Manager Multiple Vulnerabilities (1.4.2)
Apache HTTP Server NULL Pointer Dereference Vulnerability (CVE-2020-13950)